Skip to content

Validate index range in jas_matrix_bindsub - #429

Open
iliasabk wants to merge 1 commit into
jasper-software:masterfrom
iliasabk:fix/matrix-bindsub-oob
Open

iliasabk wants to merge 1 commit into
jasper-software:masterfrom
iliasabk:fix/matrix-bindsub-oob

Conversation

@iliasabk

Copy link
Copy Markdown

Summary

Fixes #419 — jas_matrix_bindsub indexes mat1->rows_ with caller-supplied r0/r1/c0/c1 and no bounds check:

for (i = 0; i < mat0->numrows_; ++i) {
    mat0->rows_[i] = mat1->rows_[r0 + i] + c0;   // OOB read when r0+i >= mat1->numrows_
}

The public inline wrappers jas_matrix_bindrow / jas_matrix_bindcol forward caller indices directly, so any application using them can hit a heap out-of-bounds read. The stored invalid row pointer is dereferenced by later accessors. The sibling jas_seq2d_bindsub does validate its range before forwarding — this path did not.

Fix

Reject r0 < 0 || c0 < 0 || r0 > r1 || c0 > c1 || r1 >= mat1->numrows_ || c1 >= mat1->numcols_ || !mat1->rows_ before mat0 is modified — so a failed bind no longer frees mat0's data either (the old code destroyed mat0 before validating nothing at all).

Testing

Reproducer (public API, no file needed):

jas_matrix_t *m1 = jas_matrix_create(2, 2);
jas_matrix_t *m0 = jas_matrix_create(1, 1);
jas_matrix_bindrow(m0, m1, 5);   // bind row 5 of a 2-row matrix
  • Before: ERROR: AddressSanitizer: READ of size 8 in jas_matrix_bindsub (jas_seq.c:242), reached via jas_matrix_bindrow (jas_seq.h:318)
  • After: jas_matrix_bindrow returns -1, no sanitizer report

jas_matrix_bindsub used the caller-supplied row/column indices to
index mat1->rows_ with no bounds checking, so an out-of-range index
read past the rows_ pointer array (heap OOB read). The read pointer
was then stored into mat0->rows_ and would be dereferenced by any
later accessor. The public inline wrappers jas_matrix_bindrow and
jas_matrix_bindcol forward caller indices directly, and unlike the
sibling jas_seq2d_bindsub no validation happened on this path.

Reject out-of-range or inverted ranges, and a mat1 without a row
array, before mat0 is modified. Validation now happens first so a
failed bind no longer frees mat0's data.

Fixes jasper-software#419.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

jas_seq.c: out-of-bounds read in public jas_matrix_bindsub API

1 participant